Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Credit card industry struggles to enforce security standard

Visa, Discover and others are taking a tougher stance on noncompliance as data breaches continue to tarnish the retail industry
By Ellen Messmer , Network World , 01/25/2007
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

Major credit card companies have made it mandatory for merchants and payment processors to comply with stringent network security rules that went into effect in mid-2005. But getting buy-in from the millions of companies that handle credit card information remains elusive.

American Express, Visa International, MasterCard Worldwide and Discover Financial Services are among the backers of the rules known as the Payment Card Industry Data Security Standard (PCI DSS).

“All the merchants are required to comply with the PCI data-security standards or face fines," says Rob Tourt, vice president of network services at Discover. Yet adoption of PCI DSS is not widespread, Tourt admits, though he wouldn’t disclose exact figures.

To improve compliance, Discover is getting more aggressive and working individually with certain merchants to make sure they get through the 12-point security plan, which covers firewalls, vulnerability assessment and encryption, among other requirements.

Discover isn’t alone in striving to turn PCI DSS into more than a paper tiger. Visa, which works more directly with acquiring banks than with merchants, also is trying to shore up low merchant adoption numbers.

Visa’s new approach calls for levying punitive fines on banks that fail to get their merchant customers to comply with the PCI standard — while promising multimillion-dollar incentive packages for banks that prod their largest customers into complying.

The broader goal is to stem the hemorrhage of sensitive customer card data lost in recent security incidents, including the data breach acknowledged earlier this month by TJX Companies, which operates retail chains including T.J. Maxx and Marshalls.

The $16 billion Framingham, Mass., retailer won’t divulge whether it complies with PCI DSS, despite the fact that Gary Crittenden, the executive vice president and CFO at American Express, sits on the TJX board.

American Express is one of the five payment-card companies that last September founded the PCI Security Standards Council, which issues the PCI security standard. The other four founding members are: Discover, JCB, MasterCard and Visa.

PCI DSS too tough?

The latest version of the standard, PCI DSS v. 1.1, includes about 200 detailed network and physical security requirements the council’s founders say they want to see become the norm for protecting payment-card information.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (3)
Login
Forgot your account info?

I think these steps areBy magenta on August 26, 2007, 6:58 pmI think these steps are necessary, a lot of people have suffered from credit card fraud, if one discomfirt to the merchant is what it takes, then good.

Reply | Read entire comment

Aquiring banks lack knowledgeBy Anonymous on July 9, 2007, 12:39 pmI was shocked when I contacted my aquiring bank to ask what I need to do to be PCI compliant. They stated I was complient because I had a privacy policy and a little...

Reply | Read entire comment

Credit card industry struggles to enforce security standardBy Anonymous on January 30, 2007, 11:28 amNice article. I'm really surprised to see the low level of compliance. I looked at the 12 points (not sure where your link was going) and it's Security 101: Use...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed